Open Jamesits opened 5 years ago
!analyze -v
0:000> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
GetUrlPageData2 (WinHttp) failed: 12002.
DUMP_CLASS: 2
DUMP_QUALIFIER: 400
FAULTING_IP:
+0
00000000`00000000 ?? ???
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 0000000000000000
ExceptionCode: 80000003 (Break instruction exception)
ExceptionFlags: 00000000
NumberParameters: 0
FAULTING_THREAD: 000062a8
DEFAULT_BUCKET_ID: STATUS_BREAKPOINT
PROCESS_NAME: SvcGuest.exe
ERROR_CODE: (NTSTATUS) 0x80000003 - {EXCEPTION} Breakpoint A breakpoint has been reached.
EXCEPTION_CODE: (HRESULT) 0x80000003 (2147483651) - One or more arguments are invalid
EXCEPTION_CODE_STR: 80000003
WATSON_BKT_PROCSTAMP: 80245fcc
WATSON_BKT_PROCVER: 1.0.3.0
PROCESS_VER_PRODUCT: SvcGuest
WATSON_BKT_MODULE: unknown
WATSON_BKT_MODVER: 0.0.0.0
WATSON_BKT_MODOFFSET: 0
WATSON_BKT_MODSTAMP: bbbbbbb4
BUILD_VERSION_STRING: 10.0.14393.2608 (rs1_release.181024-1742)
MODLIST_WITH_TSCHKSUM_HASH: 4e90de82284468c65e2ca678dbf0ff4ceb6609b4
MODLIST_SHA1_HASH: a4dfbb7c5b8aaff9657741738ae8caae9b1d448a
NTGLOBALFLAG: 0
APPLICATION_VERIFIER_FLAGS: 0
PRODUCT_TYPE: 3
SUITE_MASK: 400
DUMP_FLAGS: 8000c07
DUMP_TYPE: 0
MISSING_CLR_SYMBOL: 0
ANALYSIS_SESSION_HOST: FLUORINE
ANALYSIS_SESSION_TIME: 02-10-2019 05:43:37.0105
ANALYSIS_VERSION: 10.0.14321.1024 amd64fre
MANAGED_CODE: 1
MANAGED_ENGINE_MODULE: clr
MANAGED_ANALYSIS_PROVIDER: SOS
MANAGED_THREAD_ID: 62a8
THREAD_ATTRIBUTES:
OS_LOCALE: ENU
PROBLEM_CLASSES:
Tid [0x0]
Frame [0x00]
String [STATUS_BREAKPOINT]
Data Bucketing
BUGCHECK_STR: STATUS_BREAKPOINT
LAST_CONTROL_TRANSFER: from 00007ffda74e3ebf to 00007ffdaa245b84
STACK_TEXT:
000000a0`e74fdf78 00007ffd`a74e3ebf : 00000000`00000046 00007ffd`aa1d9b99 00000000`00000005 00007ffd`aa1cde98 : ntdll!NtWaitForSingleObject+0x14
000000a0`e74fdf80 00007ffd`a9e602a8 : 00000000`ffffffff 00007ffd`a9e8d662 000000a0`00000000 00000000`0000031c : KERNELBASE!WaitForSingleObjectEx+0x8f
000000a0`e74fe020 00007ffd`a9e5fc90 : 00000000`00000000 00000000`000e58ae 00000000`00000000 00000000`00000318 : sechost!ScSendResponseReceiveControls+0x138
000000a0`e74fe160 00007ffd`a9e5ec24 : 000000a0`e74fe2b8 00000000`00000000 00000000`000004d3 000001f2`00000001 : sechost!ScDispatcherLoop+0x138
000000a0`e74fe270 00007ffd`910396e7 : 00007ffd`91015e58 000001f2`dc5808a0 000001f2`dc4f71a0 00000000`00000000 : sechost!StartServiceCtrlDispatcherW+0x54
000000a0`e74fe2b0 00007ffd`9103c566 : 000001f2`dc580690 000001f2`dc4f71a0 000001f2`dd22d0c0 00000000`00000000 : System_ServiceProcess_ni+0x296e7
000000a0`e74fe360 00007ffd`3618d7db : 000001f2`dd22ce10 000001f2`dd22cc40 000001f2`dd22cc40 00007ffd`91047f70 : System_ServiceProcess_ni+0x2c566
000000a0`e74fe3d0 00007ffd`95796d93 : 000001f2`dd224de8 000001f2`dc555a60 00007ffd`957ae4a0 000000a0`e74fe7a0 : 0x00007ffd`3618d7db
000000a0`e74fe470 00007ffd`95796c48 : 00000000`00000004 00007ffd`957ef113 00000004`00000000 000001f2`dc4fb240 : clr!CallDescrWorkerInternal+0x83
000000a0`e74fe4b0 00007ffd`957ef606 : 000001f2`dd224de8 00000000`00000000 000000a0`e74fe698 00000000`00000000 : clr!CallDescrWorkerWithHandler+0x4e
000000a0`e74fe4f0 00007ffd`957efabf : 00000000`00000000 000000a0`e74fe5f0 00000000`00000000 000000a0`e74fe720 : clr!CallDescrWorkerReflectionWrapper+0x1a
000000a0`e74fe540 00007ffd`91c34564 : 000000a0`e74ff110 00000000`00000000 000001f2`dd224de8 00007ffd`91c9a000 : clr!RuntimeMethodHandle::InvokeMethod+0x45f
000000a0`e74feb50 00007ffd`91c1f4ee : 00000000`00000000 000001f2`dd222e30 000001f2`dd1b9ed8 00007ffd`957948b5 : mscorlib_ni+0x514564
000000a0`e74febc0 00007ffd`3618c95b : 000000a0`e74feb18 000001f2`dd226630 000001f2`dd222e30 000001f2`dd1b9ed8 : mscorlib_ni+0x4ff4ee
000000a0`e74fec40 00007ffd`3618c49a : 000001f2`dd222e30 000001f2`dd1b9ed8 000001f2`dd224de8 000001f2`dd226630 : 0x00007ffd`3618c95b
000000a0`e74fec90 00007ffd`3618c1d6 : 000000a0`e74fedf0 000001f2`dd1758a0 000000a0`e74fed30 00000000`00008000 : 0x00007ffd`3618c49a
000000a0`e74fed00 00007ffd`3618c134 : 000000a0`e74fedd8 000000a0`e74fedf0 000000a0`e74fe2f0 00000000`00008000 : 0x00007ffd`3618c1d6
000000a0`e74fedb0 00007ffd`3618bfb7 : 000001f2`dd222e30 000001f2`dd1b83a0 000000a0`e74fe2f0 00000000`00008000 : 0x00007ffd`3618c134
000000a0`e74fee40 00007ffd`3618bf16 : 000000a0`e74fef68 000001f2`dd1758a0 000000a0`e74fe2f0 00000000`00008000 : 0x00007ffd`3618bfb7
000000a0`e74fee80 00007ffd`3618be6f : 000000a0`e74fef50 000000a0`e74fef68 00000000`00000008 000001f2`dd226328 : 0x00007ffd`3618bf16
000000a0`e74fef30 00007ffd`3618bdd3 : 000001f2`dd222e48 00000000`00000000 00000000`00000008 000001f2`dd226328 : 0x00007ffd`3618be6f
000000a0`e74fefb0 00007ffd`36181b3b : 000001f2`dd222ea8 00000000`00000000 00000000`00000008 000001f2`dd226328 : 0x00007ffd`3618bdd3
000000a0`e74fefe0 00007ffd`361812e3 : 00007ffd`36069180 000001f2`dd178c68 000000a0`e74febd8 000000a0`e74feb74 : 0x00007ffd`36181b3b
000000a0`e74ff040 00007ffd`95796d93 : 000001f2`dd173148 00007ffd`36064120 00000000`00000000 00007ffd`00000000 : 0x00007ffd`361812e3
000000a0`e74ff070 00007ffd`95796c48 : 00000000`00000000 00007ffd`958e47a2 000000a0`e74ff358 00000000`00000000 : clr!CallDescrWorkerInternal+0x83
000000a0`e74ff0b0 00007ffd`9579753d : 00000000`00000001 000000a0`e74ff218 000000a0`e74ff2a0 000000a0`e74ff358 : clr!CallDescrWorkerWithHandler+0x4e
000000a0`e74ff0f0 00007ffd`957fee43 : 000000a0`e74ff1a0 00000000`00000000 00000000`00000000 00000000`00000003 : clr!MethodDescCallSite::CallTargetWorker+0xf8
000000a0`e74ff1f0 00007ffd`957ff026 : 00000000`00000003 00000000`00000000 000001f2`00000000 000001f2`dd172d48 : clr!RunMain+0x1ee
000000a0`e74ff3d0 00007ffd`957fef1b : 00007ffd`958fe040 000001f2`dc4e95e0 00007ffd`958fe040 000001f2`dc4e95e0 : clr!Assembly::ExecuteMainMethod+0xb6
000000a0`e74ff6c0 00007ffd`957fed14 : 00000000`00000000 000001f2`dc3f0000 00000000`00000000 00000000`00000000 : clr!SystemDomain::ExecuteMainMethod+0x57c
000000a0`e74ffcd0 00007ffd`957fec92 : 000001f2`dc3f0000 00007ffd`957ff0b0 00000000`00000000 00000000`00000000 : clr!ExecuteEXE+0x3f
000000a0`e74ffd40 00007ffd`957ff0c4 : ffffffff`ffffffff 00007ffd`957ff0b0 00000000`00000000 00000000`00000000 : clr!_CorExeMainInternal+0xb2
000000a0`e74ffdd0 00007ffd`98517a6d : 00000000`00000000 00007ffd`00000091 00000000`00000000 000000a0`e74ffda8 : clr!CorExeMain+0x14
000000a0`e74ffe10 00007ffd`985b10ab : 00007ffd`98510000 00007ffd`957ff0b0 00000000`00000000 00000000`00000000 : mscoreei!CorExeMain+0x112
000000a0`e74ffe70 00007ffd`a7b28364 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : mscoree!CorExeMain_Exported+0xb
000000a0`e74ffea0 00007ffd`aa20e851 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x14
000000a0`e74ffed0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x21
STACK_COMMAND: ~0s; .ecxr ; kb
THREAD_SHA1_HASH_MOD_FUNC: ea415922cb69069834cd7f4d635a252074374fba
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: d29693c449922518c928ed32ec35eaa696cecd8a
THREAD_SHA1_HASH_MOD: bef75605133fc59511bbfb94f458bd21dec04e06
FOLLOWUP_IP:
sechost!ScSendResponseReceiveControls+138
00007ffd`a9e602a8 85c0 test eax,eax
FAULT_INSTR_CODE: 850fc085
SYMBOL_STACK_INDEX: 2
SYMBOL_NAME: sechost!ScSendResponseReceiveControls+138
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: sechost
IMAGE_NAME: sechost.dll
DEBUG_FLR_IMAGE_TIMESTAMP: 5b8854f2
BUCKET_ID: STATUS_BREAKPOINT_sechost!ScSendResponseReceiveControls+138
PRIMARY_PROBLEM_CLASS: STATUS_BREAKPOINT_sechost!ScSendResponseReceiveControls+138
FAILURE_EXCEPTION_CODE: 80000003
FAILURE_IMAGE_NAME: sechost.dll
BUCKET_ID_IMAGE_STR: sechost.dll
FAILURE_MODULE_NAME: sechost
BUCKET_ID_MODULE_STR: sechost
FAILURE_FUNCTION_NAME: ScSendResponseReceiveControls
BUCKET_ID_FUNCTION_STR: ScSendResponseReceiveControls
BUCKET_ID_OFFSET: 138
BUCKET_ID_MODTIMEDATESTAMP: 5b8854f2
BUCKET_ID_MODCHECKSUM: 5dd8b
BUCKET_ID_MODVER_STR: 10.0.14393.2515
BUCKET_ID_PREFIX_STR: STATUS_BREAKPOINT_
FAILURE_PROBLEM_CLASS: STATUS_BREAKPOINT
FAILURE_SYMBOL_NAME: sechost.dll!ScSendResponseReceiveControls
FAILURE_BUCKET_ID: STATUS_BREAKPOINT_80000003_sechost.dll!ScSendResponseReceiveControls
WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/SvcGuest.exe/1.0.3.0/80245fcc/unknown/0.0.0.0/bbbbbbb4/80000003/00000000.htm?Retriage=1
TARGET_TIME: 2019-02-10T05:18:18.000Z
OSBUILD: 14393
OSSERVICEPACK: 2608
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 Server TerminalServer DataCenter SingleUserTS
USER_LCID: 0
OSBUILD_TIMESTAMP: 2018-10-25 03:21:59
BUILDDATESTAMP_STR: 181024-1742
BUILDLAB_STR: rs1_release
BUILDOSVER_STR: 10.0.14393.2608
ANALYSIS_SESSION_ELAPSED_TIME: 1d27f
ANALYSIS_SOURCE: UM
FAILURE_ID_HASH_STRING: um:status_breakpoint_80000003_sechost.dll!scsendresponsereceivecontrols
FAILURE_ID_HASH: {bb63494f-e1c6-d49e-12fa-866691bbfd47}
Followup: MachineOwner
---------
0:000> !CLRStack -a
OS Thread Id: 0x62a8 (0)
Child SP IP Call Site
000000a0e74fe2d8 00007ffdaa245b84 [InlinedCallFrame: 000000a0e74fe2d8] System.ServiceProcess.NativeMethods.StartServiceCtrlDispatcher(IntPtr)
000000a0e74fe2d8 00007ffd910396e7 [InlinedCallFrame: 000000a0e74fe2d8] System.ServiceProcess.NativeMethods.StartServiceCtrlDispatcher(IntPtr)
000000a0e74fe2b0 00007ffd910396e7 DomainBoundILStubClass.IL_STUB_PInvoke(IntPtr)
PARAMETERS:
<no data>
000000a0e74fe360 00007ffd9103c566 System.ServiceProcess.ServiceBase.Run(System.ServiceProcess.ServiceBase[])
PARAMETERS:
services (<CLR reg>) = 0x000001f2dd184ea0
LOCALS:
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
000000a0e74fe3d0 00007ffd3618d7db SvcGuest.Program.OnExecute()
PARAMETERS:
this = <no data>
LOCALS:
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
000000a0e74fe698 00007ffd95796d93 [DebuggerU2MCatchHandlerFrame: 000000a0e74fe698]
000000a0e74fe9d8 00007ffd95796d93 [HelperMethodFrame_PROTECTOBJ: 000000a0e74fe9d8] System.RuntimeMethodHandle.InvokeMethod(System.Object, System.Object[], System.Signature, Boolean)
000000a0e74feb50 00007ffd91c34564 System.Reflection.RuntimeMethodInfo.UnsafeInvokeInternal(System.Object, System.Object[], System.Object[]) [f:\dd\ndp\clr\src\BCL\system\reflection\methodinfo.cs @ 767]
PARAMETERS:
this = <no data>
obj = <no data>
parameters = <no data>
arguments = <no data>
LOCALS:
<no data>
<no data>
000000a0e74febc0 00007ffd91c1f4ee System.Reflection.RuntimeMethodInfo.Invoke(System.Object, System.Reflection.BindingFlags, System.Reflection.Binder, System.Object[], System.Globalization.CultureInfo) [f:\dd\ndp\clr\src\BCL\system\reflection\methodinfo.cs @ 735]
PARAMETERS:
this = <no data>
obj = <no data>
invokeAttr = <no data>
binder = <no data>
parameters = <no data>
culture = <no data>
LOCALS:
<no data>
<no data>
<no data>
<no data>
000000a0e74fec40 00007ffd3618c95b McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention.Invoke(System.Reflection.MethodInfo, System.Object, System.Object[])
PARAMETERS:
this = <no data>
method (<CLR reg>) = 0x000001f2dd17b340
instance = <no data>
arguments = <no data>
LOCALS:
<no data>
000000a0e74fec90 00007ffd3618c49a McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+d__1.MoveNext()
PARAMETERS:
this (0x000000a0e74fed00) = 0x000000a0e74fedf0
LOCALS:
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
<no data>
000000a0e74fed00 00007ffd3618c1d6 System.Runtime.CompilerServices.AsyncTaskMethodBuilder`1[[System.Int32, mscorlib]].Start[[McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+d__1, McMaster.Extensions.CommandLineUtils]](d__1 ByRef) [f:\dd\ndp\clr\src\BCL\system\runtime\compilerservices\AsyncMethodBuilder.cs @ 477]
PARAMETERS:
this = <no data>
stateMachine = <no data>
LOCALS:
<no data>
000000a0e74fedb0 00007ffd3618c134 McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention.OnExecute(McMaster.Extensions.CommandLineUtils.Conventions.ConventionContext)
PARAMETERS:
this = <no data>
context = <no data>
LOCALS:
<no data>
<no data>
000000a0e74fee40 00007ffd3618bfb7 McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+c__DisplayClass0_0+b__0>d.MoveNext()
PARAMETERS:
this (0x000000a0e74fee80) = 0x000000a0e74fef68
LOCALS:
<no data>
<no data>
<no data>
<no data>
<no data>
000000a0e74fee80 00007ffd3618bf16 System.Runtime.CompilerServices.AsyncTaskMethodBuilder`1[[System.Int32, mscorlib]].Start[[McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+c__DisplayClass0_0+b__0>d, McMaster.Extensions.CommandLineUtils]](b__0>d ByRef) [f:\dd\ndp\clr\src\BCL\system\runtime\compilerservices\AsyncMethodBuilder.cs @ 477]
PARAMETERS:
this = <no data>
stateMachine = <no data>
LOCALS:
<no data>
000000a0e74fef30 00007ffd3618be6f McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+c__DisplayClass0_0.b__0()
PARAMETERS:
this = <no data>
LOCALS:
<no data>
<no data>
000000a0e74fefb0 00007ffd3618bdd3 McMaster.Extensions.CommandLineUtils.CommandLineApplication+c__DisplayClass126_0.b__0()
PARAMETERS:
this = <no data>
LOCALS:
<no data>
000000a0e74fefe0 00007ffd36181b3b McMaster.Extensions.CommandLineUtils.CommandLineApplication.Execute[[System.__Canon, mscorlib]](McMaster.Extensions.CommandLineUtils.Abstractions.CommandLineContext)
PARAMETERS:
context (0x000000a0e74ff048) = 0x000001f2dd178c68
LOCALS:
0x000000a0e74ff008 = 0x000001f2dd179520
0x000000a0e74ff014 = 0x0000000000000000
<no data>
000000a0e74ff040 00007ffd361812e3 SvcGuest.Program.Main(System.String[])
PARAMETERS:
args = <no data>
000000a0e74ff2a0 00007ffd95796d93 [GCFrame: 000000a0e74ff2a0]
0:000> !dso
OS Thread Id: 0x62a8 (0)
RSP/REG Object Name
000000A0E74FE320 000001f2dd184ea0 System.ServiceProcess.ServiceBase[]
000000A0E74FE398 000001f2dd22cc40 SvcGuest.ServiceInterface.Service
000000A0E74FE3A0 000001f2dd171588 System.AppDomain
000000A0E74FE3D8 000001f2dd22cc40 SvcGuest.ServiceInterface.Service
000000A0E74FE3E0 000001f2dd22cc40 SvcGuest.ServiceInterface.Service
000000A0E74FE5F8 000001f2dd182020 SvcGuest.Program
000000A0E74FE608 000001f2dd1823a8 System.Signature
000000A0E74FE910 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FEB30 000001f2dd17b340 System.Reflection.RuntimeMethodInfo
000000A0E74FEB38 000001f2dd182020 SvcGuest.Program
000000A0E74FEB80 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FEB98 000001f2dd17b340 System.Reflection.RuntimeMethodInfo
000000A0E74FEBA0 000001f2dd182020 SvcGuest.Program
000000A0E74FEBA8 000001f2dd182428 System.Object[] (System.Object[])
000000A0E74FEBD0 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FEBF0 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FEC08 000001f2dd17b340 System.Reflection.RuntimeMethodInfo
000000A0E74FEC18 000001f2dd17b340 System.Reflection.RuntimeMethodInfo
000000A0E74FEC28 000001f2dd182020 SvcGuest.Program
000000A0E74FEC58 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FEC78 000001f2dd180c80 McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention
000000A0E74FEC80 000001f2dd182428 System.Object[] (System.Object[])
000000A0E74FEC98 000001f2dd1b9ed8 Microsoft.Win32.SafeHandles.SafeLocalAllocHandle
000000A0E74FED40 000001f2dd174c00 System.Threading.Thread
000000A0E74FEDF0 000001f2dd17a650 McMaster.Extensions.CommandLineUtils.Conventions.ConventionContext
000000A0E74FEDF8 000001f2dd180c80 McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention
000000A0E74FEE48 000001f2dd1b83a0 System.__ComObject
000000A0E74FEEC0 000001f2dd174c00 System.Threading.Thread
000000A0E74FEF10 000001f2dd222e48 System.Management.ManagementPath
000000A0E74FEF68 000001f2dd180c98 McMaster.Extensions.CommandLineUtils.Conventions.ExecuteMethodConvention+<>c__DisplayClass0_0
000000A0E74FEF98 000001f2dd1b8478 System.Collections.Hashtable
000000A0E74FEFB0 000001f2dd222e48 System.Management.ManagementPath
000000A0E74FEFD0 000001f2dd1b8478 System.Collections.Hashtable
000000A0E74FF008 000001f2dd179520 McMaster.Extensions.CommandLineUtils.CommandLineApplication`1[[SvcGuest.Program, SvcGuest]]
000000A0E74FF048 000001f2dd178c68 McMaster.Extensions.CommandLineUtils.Internal.DefaultCommandLineContext
000000A0E74FF070 000001f2dd173148 System.String -Infinity
000000A0E74FF158 000001f2dd173148 System.String -Infinity
000000A0E74FF218 000001f2dd173148 System.String -Infinity
000000A0E74FF3E8 000001f2dd172d48 System.String[]
000000A0E74FF958 000001f2dd171440 System.SharedStatics
Note: Under Windows 10 2004 (20H1), if VBS is enabled, WMI performance is going to be very bad
Observed on Fluorine. Private working set ~10.3GiB.
At that time, Windows Update on Fluorine is f*cking up everything (100% CPU and lots of mem), WMI service is responding very slowly too.
Heap Stat
Objects on GC Heap